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Abstract 

This paper is aimed at providing a uniform framework for reasoning about beliefs of multiple agents and 
their fusion. In the first part of the paper, we develop logics for reasoning about cautiously merged beliefs 
of agents with difi'erent degrees of reliability. The logics are obtained by combining the multi-agent epistemic 
logic and multi-sources reasoning systems. Every ordering for the reliability of the agents is represented by a 
modal operator, so we can reason with the merged results under difi'erent situations. The fusion is cautious 
in the sense that if an agent's belief is in confiict with those of higher priorities, then his belief is completely 
discarded from the merged result. We consider two strategies for the cautious merging of beliefs. In the first 
one, if inconsistency occurs at some level, then all beliefs at the lower levels are discarded simultaneously, so it 
is called level cutting strategy. For the second one, only the level at which the inconsistency occurs is skipped, 
so it is called level skipping strategy. The formal semantics and axiomatic systems for these two strategies are 
presented. In the second part, we extend the logics both syntactically and semantically to cover some more 
sophisticated belief fusion and revision operators. While most existing approaches treat belief fusion operators 
as meta-level constructs, these operators are directly incorporated into our object logic language. Thus it 
is possible to reason not only with the merged results but also about the fusion process in our logics. The 
relationship of our extended logics with the conditional logics of belief revision is also discussed. 
Key Words: Epistemic logic, multi-sources reasoning, database merging, belief fusion, belief revision, multi- 
agent systems. 



1 Introduction 

Recently, there has been much attention on the infoglut problem in information retrieval research due to the rapid 
growth of internet information. If a keyword is input to a commonly-used search engine, it is not unusual to get 
back a list of thousands of web pages, so the real difficulty is not how to find information, but how to find useful 
information. To circumvent the problem, many software agents have been designed to do the information search 
works. The agents can search through the web and try to find and filter out information for matching the user's 
need. However, not all internet information sources are reliable. Some web sites are out-of-date, some news provide 
wrong information, and someone even intentionally spreads rumor or deceives by anonymity. Thus an important 
task of information search agents is how to merge so much information coming from different sources according to 
their degrees of reliability. 

In Bq], an agent is characterized by mental attitudes, such as knowledge, belief, obligation, and commitment. 



This view of agent, in accordance with the intentional stance proposed in |22 , has been widely accepted as a 
convenient way for the analysis and description of complex systems |7^. From this viewpoint, each information 
provider can be considered as an agent and the information provided by the agent corresponds to his belief, so our 
problem is also that of merging beliefs from different agents. 

The philosophical analysis of these mental attitudes has motivated the development of many non-classical 
logical systems [Q. In particular, the analysis of informational attitudes, such as knowledge and belief, has been a 
traditional concern of epistemology, a very important branch of philosophy since the ancient times. To answer the 
basic questions such as "What is knowledge?" "What can we know" and "What are the characteristic properties 
of knowledge?" , some formalism more rigorous than natural language is needed. This results in the development of 

*A preliminary version of the paper has appeared in |U5|. 
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the so-called epistemic logic ||3^. This kind of logic has attracted much attention of researchers from diverse fields 
such as artificial intelligence(AI), economics, linguistics, and theoretical computer science. Among them, the AI 
researchers and computer scientist have elaborated some technically sophisticated formalisms and applied them to 
the analysis of distributed and multi- agent systems p4[ . 

Though the original epistemic logic in philosophy is mainly about the single-agent case, the application to 
AI and computer science put its emphasis on the interaction of agents, so multi-agent epistemic logic is urgently 
needed. One representative example of such logic is proposed by Fagin et al.[0. In their logic, the knowledge 
of each agent is represented by a normal modal operator so if no interactions between agents occur, this is 
not more than a multi-modal logic. However, the most novel feature of their logic is the consideration of common 
knowledge and distributed knowledge among a group of agents. While common knowledge is the facts that everyone 
knows, everyone knows that everyone knows, everyone knows that everyone knows that everyone knows, and so 
on, distributed knowledge is that can be deduced by pooling together the knowledge of everyone, so it is the latter 
that really concerns the fusion of knowledge among agents. However, the term "knowledge" is used in a broad 
sense in to cover the cases of belief and information]^ Though it is required that proper knowledge must be 
true, the belief of an agent may be wrong, so there will be conflicts in general in the beliefs to be merged. In this 
case, everything can be deduced from the distributed beliefs due to the notorious omniscience property of epistemic 
logic, so the merged result will be useless to further reasoning. 

Instead of directly put all beliefs of the agents together, there are also many sophisticated techniques for 
knowledge base merging ||, |, |, |l5Hl|, |4^, ||, ll ||, || ||, ||, |5|, || . Most of the approaches treats belief fusion 



operators as meta-level constructs, so given a set of knowledge bases, this kind of fusion operators will return the 
merged results. Some of the works propose concrete operators which can be used directly in the fusion process, 
while the others stipulate the desirable properties of reasonable belief fusion operators by postulates. However, few 
of the approaches provides the capability of reasoning about the fusion process. One of the few exceptions is the 
work of multi-source reasoning^]. 

Multi-source reasoning is to model the fusion process of multiple databases in a modal logic. The context of 
the work is to merge a set of databases according to a total ordering on the set to be merged. Each database is a 
finite and satisfiable set of literals. Two attitudes for merging are considered. According to the suspicious attitude, 
if a database contains a literal inconsistent with those in the databases of higher reliability, then the database is 
completely discarded in the merged result. On the other hand, according to the trusting attitude, if a literal in 
a database is inconsistent with those in the databases of higher reliability, only the literal is discarded, and other 
literals in the database will be still considered if they are consistent with those in the databases of higher reliability. 

Since multi-source reasoning is modelled in a modal logic framework, it is very suitable for the integration 
with epistemic logic. The restriction here is that each database must be a set of literals in multi-source reasoning, 
however, in the multi-agent epistemic logic, it is expected that more complex compound formulas will be believed 
by agents. Therefore, we have to extend the multi-sources reasoning to the more general case. To achieve the 
purpose, the distributed knowledge operators in multi-agent epistemic logic may help. What we have to do is to 
adapt the multi-agent epistemic logic so that the distributed knowledge among a group of agents with reliability 
ordering can also be defined. However, since the set of facts believed by an agent is at least closed under classical 
logical equivalence, the trusting attitude does not work here. For example, if p and q are both believed by an agent 
and -ip V -iq is believed by another agent with higher reliability, then by trusting attitude, one of p or q should be 
in the merged result (assume there do not exist other conflicts), however, it is obvious that the belief of the first 
agent is equivalent to p A q and if it is expressed in this way, then no belief of the first agent (except the obvious 
tautology) should be included in the merged belief. Thus, we will only consider the merging of beliefs according 
to the suspicious attitude, so this approach is very cautious from the viewpoint of belief fusion. However, we will 
show that the fusion according to the trusting attitude can also be simulated in our logic, though the simulation is 
syntax-dependent. We consider two strategies for the cautious merging of beliefs. In the first one, if inconsistency 
occurs at some level, then all beliefs at the lower levels are discarded simultaneously, so it is called level cutting 
strategy. For the second one, only the level at which the inconsistency occurs is skipped, so it is called level skipping 
strategy. 

The logics integrate multi-source reasoning into multi-agent epistemic logic, so it enhance the reasoning capa- 
bility of the latter. However, since the fusion technique used in the logics is essentially the so-called base revision in 
[ p6| , it is too cautious in some cases. Thus we would also like to consider the extension of the logics with some more 

^More precisely, the logic for belief is called doxastic logic. However, here we will use the three terms knowledge, belief, and 
information interchangeably, so epistemic logic is assumed to cover all these notions. 



sophisticated fusion operators proposed in the hteratures. We show that the muhi-agent epistemic logic framework 
can accommodate these beUef fusion operators to a large extent both syntactically and semantically. This means 
that the belief fusion operators as a standard add-on of multi-agent epistemic logic should be expectable. 

The rest of the paper is organized as follows. In the next section, the multi-agent epistemic logic and multi- 
sources reasoning are reviewed. Then the logics integrating cautious fusion into multi-agent epistemic logic are 
presented. The level cutting and skipping strategies are presented respectively in section ^ and ^. The syntax, 
semantics, and axiomatic systems of the logics will be given. In section |5| the basic logics are compared with their 
ancestors and another cautious inconsistency handling technique. In section |^ and , accompanied by the brief 
introductions of some of the most important belief fusion or revision techniques, the possible extensions of our 
basic logics for accommodating them are presented. Finally, some further research directions are discussed in the 
concluding section. 



2 Logical Preliminary 

In this section, we review the syntax, semantics and some notations for multi-agent epistemic logic and multi-sources 
reasoning. 

2.1 Multi-agent epistemic logic 

In js^, some variants of epistemic logic systems are presented. The most basic one with distributed belief is 
called by following the naming convention in jlj], with n being the number of agents and D denoting the 
distributed belief operators. In the system, no properties except logical omniscience are imposed on the agents' 
beliefs. Nevertheless, in the following, we will assume the belief of each individual agent is consistent though the 
collective ones of several agents may be not, so the system will be KD^ where the additional axiom D is added to 
for ensuring the consistency of each agent's belief. Q 

Assume we have n agents and a set $o of countably many atomic propositions, then the set of well- formed 
formulas(wff) for the logic KD^ is the least set containing $0 and closed under the following formation rules]^ 

• if </? is a wff, so are -^ip, Biip, and Dcf for all I < i, j < n and nonempty G C {1, . . . , n}, and 

• if <y9 and ip are wffs, then ip \/ ip is, too. 

As usual, other classical Boolean connectives A (and), D (implication), = (equivalence), T (tautology), and _L 
(contradiction) can be defined as abbreviations. 

The intuitive meaning of Bi(p is "The agent i believes (p." , whereas that for Dcf is "The group of agents G has 
distributed belief ip." . The possible- worlds semantics provides a general framework for the modeling of knowledge 
and belief In the semantics, an agent's belief state corresponds to the extent to which he can determine what 
world he is in. In a given world, the belief state determines the set of worlds that the agent considers possible. 
Then an agent is said to believe a fact ip if ip is true in all worlds in this set. Since the distributed belief of a group 
is the result of pooling together the individual beliefs of its members, this can be achieved by intersecting the sets 
of worlds that each agent in the groups considers possible. 

Formally, a KD^ model is a tuple {W, (Si)i<i<„, V), where 

• is a set of possible worlds, 

• Bi C W X W is a serial binary relation on W for 1 < i < n, |^ 



y : $0 ^ 2 is a truth assignment mapping each atomic proposition to the set of worlds in which it is true. 



In the following, we will use some standard notations for binary relations. If 7?. C yl x _B is a binary relation 
between A and B, we will write TZ{a,b) for (a, 6) e TZ and TZ{a) for the subset {6 G -B | TZ{a,b)}. Thus for 

^Though it is well accepted that KD45^ is more appropriate for modeling of belief with positive and negative introspection (axioms 
4 and 5), we adopt the KD^ system for emphasizing the agents may represent databases and their beliefs may be just the facts stored 
in the databases and their consequences. 

^In [3l|], the modal operators are denoted by Ki instead of Bi 

''A relation 7?. on is serial if '\/w3u'R,(w, u). 



any w £ W, Bi{w) is a subset of W. Informally, Bi{w) is the set of worlds that agent i considers possible 
under w according to his belief. The informal intuition is reflected in the definition of satisfaction relation. Let 
M = (W, {Bi)i<i<n,V) be a KD^ model and $ be the set of wffs, then the satisfaction relation \^mQ x $ is 
defined by the following inductive rules (we will use the infix notation for the relation and omit the subscript M 
for convenience): 

1. w \^ p iS w G V{p) for any p S $0, 

2. w \^ -i</7 iff w ^ ip, 

3. w\^ip\/'il'iSw\=ipoTw\=il), 

4:. w \= BiLp iff for all u G Bi{w), u \= ip, 

5. w ^ Dgp iff for all u e HieG ^ii'^)^ u \^ ip. 

The notion of validity is defined from the satisfaction relation. A wff ip is valid in M, denoted by if for 

every w G W, w \=m y^, and valid in a class of models A4, written as '/'i if for a-U M E A4, 'f- 



2.2 Multi-sources reasoning 

The context of multi-sources reasoning is the merging of n databases. To encode the degrees of reliability of these 
databases, the total ordering on a subset of {1, . . . , n} is used. Let TOn denote the set of all possible total orders 
on the subsets of {1, . . . , n}, <i>o denote a finite set of atomic propositions and £($0) be the classical propositional 
language formed from $0, then the set of wffs for logic FU„ (originally called FUSION in is the least set 
containing <I>o and {[0]v? : p & £($0), O £ TOn} and being closed under Boolean connectives. If O is the ordering 
ii > J2 > • • • > im for some {ii, . . . , z„i} C {1, . . . , n}, then the wff [0]ip means that ip holds after merging the 
databases ii, . . . , according to the specified ordering. In this case, O > im+i denotes «i > Z2 > • • • > «m > hn+i- 
Furthermore, the set {ii, 12, ... , im} is called the domain of O and is denoted by S{0). 

Let Lii($o) denote the set of literals in £($o)-0 In the context of multi-sources reasoning, assume DBi, . . . , DBn 
are n databases, where each DBi is a finite satisfiable subset of Lit{^o), then the informal semantics for the merging 
databases can be given according to two attitudes. For the suspicious attitude, only the case of n = 2 is given in 
[ p^ , where the definition of DBiy2 is defined by 

f DBi U DB2 if DBi U DB2 is consistent, 
UBiy2 - I otherwise. 

On the other hand, for the trusting attitude, the definition of DBq is given in the following recursive formula 

DBo>, = DBo U{leDB,:l<^ DBq}, 

where I is the complementary of I. Then the intended meaning of [0]p is DBq |=cl ^, where CL denotes classical 
propositional reasoning. 

Thus an FU„ model is a tuple {W, [Tli)i<i<n, V), where W and V are as defined in KD^ models, and each TZi 
is a serial binary relation on The clause for satisfaction of the formula [0\p is then 

w \= [0]p iff for all u G TLo{w), u\= ip, 

where TZq is defined from TZiS according to two attitudes. For the suspicious attitude, 



7?-i>2(w) 



7^l(^^;) if 7^l(^t;) n 7^2(w) = 0, 

TZi{w) fMZ2{w) otherwise. 



for all w G W . For the trusting attitude, we need some auxihary notations. Let / : 2^ x 2^ ^ 2^**(*«) be defined 
as 

f{S, T) = {le Lit{<pQ) : G S{w ^ I) A 3w G T{w ^ I)}, 

literal is an atom or a negated atom. 
®In |l5|,it is assumed that each TZi is an equivalence relation. However, since nested modalities are not allowed in FUn, the difference 
is inessential. 



i.e., f{S, T) is the set of literals true in all worlds of S and some worlds of T. Then for any w E W, 



^Zo>^{w) = 7^oH n{ueW:u ^ f\f{TZ,{w),TZo{w))}. 

Note that if each TZi{w) denotes the set of possible worlds in which the literals in DBi are all true, then 
f{Tii{w),Tio{w)) is just the set {I G DBi ■ T- ^ DBq}, so TZo>iiw) is exactly the set of possible worlds satis- 
fying all literals in DBo>i- 

An axiomatic system for FU„ based on trusting attitude semantics is proposed in a recent paper fl^ . One key 
axiom of that system is as follows 

A -^[0]^l d[0> i]l, 

where I is a literal. Thus a severe restriction of FU„ is the background databases DBi 's can contain only literals 
which may be not the case in general practice. Though from the semantic viewpoint, there is no essential difficulty 
to lift the restriction, however the key axiom is no longer valid when the databases contain general formulas. On 
the other hand, for the suspicious semantics, the merged database in fact contains the distributed belief of the two 
databases if they are consistent. However, since distributed belief operator is not in the language of FU„, the modal 
operator [O] can only be characterized by the modal operators [i] for i € S{0). Nevertheless, unless is a literal, 
it seems difficult (if not impossible) to define Di,2<^ in terms of the two individual agents' belief. Thus, a natural 
solution to merge general databases in the suspicious semantics is to introduce the distributed belief operators into 
the language of FU„. This is exactly what we will do in the following. 



3 Level Cutting Strategy 

To unify the notations from multi-agent epistemic logic and multi-sources reasoning, we will use the language DBFJ^ 
(for distributed belief fusion and cutting strategy) defined as follows. The wffs of DBF^ is the least set containing 
4>o and being closed under Boolean connectives and the following rule: 

• if <y9 is a wff, so are [G]ip and [0]ip for any nonempty G C {1, . . . , n} and O G TOn. 

When G is a singleton {i} and O is the unique total order on {z}, we will use to denote both [G](/3 and [0]ip. 
Thus and [G]lp correspond respectively to BiLp and Dq^P in KD^, so DBFJ^ is an extension of the multi-agent 
epistemic logic with distributed belief operators. On the other hand, [0]^p and are precisely those in FU„, 
so DBF^ is also a generalization of multi-sources reasoning system. However, note that nested modalities are not 
allowed in FU„, whereas this is not restricted in DBF^ any more. Thus, for example, we can include a wff [j]Lp in 
a database DBi which means that DBi has the information that ip is in j . 

Let Q be a partial order on {1, 2, • • • , k} for some k < n and Oq be the set of all total orders on {1, 2, • • • , k} 
containing Q, then define [Q]ip as the abbreviation of AoeOQl^^"^- Thus the restriction of the modalities to total 
orders is not essential since a partial order can be replaced by the set of total orders compatible with it. 

For the semantics, a DBFJ^ model is just a FU„ model {W, {TZi)i<i<n, V). The clauses for the satisfaction of 
wffs are defined exactly as in FU„ model in addition to a clause for the [G] operator which is the one for distributed 
knowledge in KD^. However, the relation TZq is now defined in an inductive way: 



/ 7^o(w) 

y TZo[w) n TZi[w) 



otherwise. 



for any w G W . Let O — (ii > i2 > ■ ■ ■ > im) and define Gj — {ii, 12 ■ ■ ■ , ij} for 1 < j < m and assume k is the 
largest j such that HieGfc ^i(^) 0; then we have 

In other words, the beliefs from the agents after the level k are completely discarded in the merged result. The 
rationale behind this is if belief in level fc -I- 1 is not acceptable, neither any belief in a less reliable level, so this is 
a very cautious attitude to belief fusion. 



1 A'vimTm* 




P: all tautologies of the propositional calculus 




(ji. ([Lrlip A [(j\{(p D tp)) J [U\ip 




G2: -^\i]± 




G3: [Gi]v? D [G2](/3 if Gi c G2 




01: -n[S{0 > i)]± D {[O > % = [S{0 > i)]ip) 




uz. [0(^0' > — ) > i\ip = [<~J\^) 




2. Rules of Inference: 




Rl (Modus ponens, MP): 




R2 (Generalization, Gen): 


[G]^ 



Figure 1: The axiomatic system for DBF^ 



The notion of validity in DBF^ is defined just as that for KD^. The notation Hdbf= <f denotes that (p is valid 
in all DBF^ model and the subscript is usually omitted if there is no confusion. The valid wffs of DBF^ can be 
captured by the axiomatic system in Fig |^. 

The axioms G1-G3 and rule R2 are those for KD^. Gl and rule R2 are properties of knowledge for perfect 
reasoners. They also are the causes of the notorious logical omniscience problem. However, it is appropriate to 
describe implicit information in this way. G2 is the requirement that the belief of each individual agent is consistent. 
G3 is a characteristic property of distributed knowledge. The larger the subgroup, the more knowledge it possesses. 
In | |3l[ |, another axiom related distributed knowledge and individual ones is added. That is, 

however, we do not need this because we identify [i\ip and which respectively correspond to Biip and D^i^ip 

in KD^. The two axioms 01 and 02 define the merged belief in terms of distributed belief in a recursive way. 01 
is the case when C\jes{o>i) T^ii'^) whereas 02 is the opposite case. 

The derivability in the system is defined as follows. Let S U {(p} be a subset of wffs, then ip is derivable from 
S in the system DBFJ^ , written as E I-dbf^, 'fi, if there is a finite sequence tpi, . . . , ipm such that every tpi is an 
instance of an axiom schema, a wff in E, or obtainable from earlier ipj^s by application of an inference rule. When 
E = 0, we simply write Kdef^ f- We will drop the subscript when no confusion occurs. We have the soundness 
and completeness results for the system DBF^. 

Theorem 1 For any wff of DBF^ , \= p iffhp. 

Proof: The proof of all theorems and propositions can be found in the appendix. □ 
Some basic theorems can be derived from the system. 

Proposition 1 For any O — (ii > i2 > ■ ■ ■ > im) o,nd Gj ~ {ii, 12 • ■ • , *j}(l 5: j ^ "i), we have 

1. h (-i[Gj]^ A [Gj+i]_L) D ([0](/3 = [Gjjtys), where the wff [Gj+iJ-L is deleted from the antecedent when j = to. 

2. h([0]vpA[0](^D^))D[0]V, 



3. h ^[0]±, 



Proposition ^ 1 shows that any total order can be cut into a head and a tail according to some consistency level, 
and the merged belief according to the ordering is just the distributed belief of the agents from the head part. 
Proposition ^2 and ^4 show that merged belief inherits the properties of the distributed one since the former is 
equivalent to the latter for the head part of the ordering. Furthermore, Proposition |l|.3 shows that belief fusion 
keeps consistency. 

4 Level Skipping Strategy 

Though level cutting strategy is useful in practice, it is sometimes too cautious from the viewpoint of information 
fusion. A less cautious strategy is to skip only the agent causing inconsistency and continue to consider the next 
level. The strategy corresponds to the suspicious attitude of multi-sources reasoning and has been used in belief 
revision by NebelBq]. This strategy is easily obtained by modifying the inductive definition of 7io>i as follows. 



for any w G W. 

According to the definition, [O > i](p will be equivalent to the distributed fusion of [0](p and [i]ip when the 
belief of i is consistent with the merged belief of O, so to axiomatize reasoning under the strategy, we must view 
O as a virtual agent and consider the distributed belief between O and i. However, to get a bit more general, we 
will consider the distributed belief among a group of virtual agents. Thus, we define the wH's of the logic DBFfj(for 
skipping strategy) as the least set containing $o and being closed under Boolean connectives and the following 
rule: 

• if (y9 is a wff, so are [fi]<p for any nonempty Q C TOn- 

When O is a singleton {O}, we will write [0]tf instead [{0}](^. li VI ~ {Oi, . . . , Om} is such that |(5(0i)| — 1 for 
all i's, then [fi] is the distributed belief operator among ordinary agents. Therefore, the language is more general 
than that of DBF^. 

For the semantics, a DBF^ model is still a DBF^ model, however, the satisfaction clauses for [O] and [G] 
operators are replaced by the following 

w ^ [^]'^ iff for all u G TZfi{w),u \= ip, 

where TZq,{w) — noeo^o('^) defined inductively at the beginning of the section. Given this language 

and semantics, the valid wffs of DBF^ is capture by the axiomatic system in Fig ||. 

The axioms VI- V3 and rule R2' correspond to G1-G3 and R2 for distributed belief, but now for virtual agents 
instead of ordinary agents. Nevertheless, since an ordinary agent is a special case of the virtual one, these in fact 
also cover G1-G3 and R2. 01' and 02' are axioms for describing the level skipping strategy and correspond exactly 
to the inductive definition of TZo>i, where VI in these two axioms denote any subset (empty or not) of TOn- We 
can still have the soundness and completeness theorem. 

Theorem 2 For any wff o/DBFfj, \= ip iff\-ip. 

Since operator [O] is a special case of the properties ^2 and ^.4 hold trivially for DBF^ . The property |l|.3 can 
be easily proved by using V2, 01' and 02'. However, it is unclear whether a counterpart of property ^1 can be 
given. 

5 Related works 

In this section, some important works related to the above-mentioned logical systems will be investigated. In the 
preceding sections, the strong dependence of our logics on multi-sources reasoning and multi-agent epistemic logic 
has been emphasized, so we will start from the comparison with them. Then we also compare DBF^ with the 
possibilistic logic approach to inconsistency handling which is known to be very cautious in belief fusion||^. 




1. Axioms: 

P: all tautologies of the propositional calculus 

VI: {[n]ipA[n]{ip D iIj)) d [n]ip 

V2: 

V3: [ni]ip D [n2]ip ani c n2 

01': -^[{0,i}]±D {[nu{0>i}]ip= [QU{0,i}]ip) 
02': [{O, i}]± D {[n U {O > i}]ip =[nu {0}]ip) 

2. Rules of Inference: 

Rl (Modus ponens, MP): 



R2' (Generalization, Gen): 



Figure 2: The axiomatic system for DBF^ 
5.1 Multi-sources reasoning 

Since the original motivation of multi-sources reasoning is to model database me rging, we will also consider the 



relationship of our logic to multi-sources reasoning in this context. In section 2^, it is assumed that <E>o is finite 
and each DBi is a finite satisfiable subset of Lit{^o). Let CLS{^o) be the set of clauses in jC($o)[|: then in FU„, 
each DBi is characterized by a wff 

= A{[i]l-l(^DB,}A 

A{-Mc : c e CLS{<i>o), DB, \/cl c}, 

and the reasoning problem is to decide whether the foUowing holds: 

n 
i=l 

for some given O and </? G £($o)- The formula i/jj asserts not only the explicit information in DBi but also the 
default negative information about it. However, since in our logic, no restrictions arc put on the wffs in databases, 
this kind of default wffs are potentially infinite, so we will only assert a weaker form of wff. Let G be a subset 
of {1,2,..., n}, then G is consistent if IJ^gg DBi is classically consistent, otherwise, it is inconsistent. A subset 
G is a maximal consistent agent group if G is consistent and for any i^G, GU{z}is inconsistent. Let MCAG 
denote the class of all maximal consistent agent groups and redefine ipi ^ /\{[i\Lp : ip ^ DBi}, then we can define 
the formula -0 representing the databases as 

n 

i=l GeMCAG 

Thus the reasoning problem in our logic is to decide whether \- ip Z) [O] ip holds in our system for some given O and 
If. Let us use an example to illustrate the application. 

'^A clause is a disjunction of literals. 



Example 1 Assume there are four databases DBi — {p}, DB2 = {q}, DB^ = {^pV ^q}, and DB4 = {r, s}, where 
p,q,r, and s are prepositional symbols, then according to the above discussion, 



= [l]p A [2]q A [3]{^p V ^q) A [4](r A s) A -[{1, 2, 4}]± A -[{1, 3, 4}]± A -[{2, 3, 4}]±. 

By using level cutting strategy, we have the following reasoning steps: 

Lip D (-[{1,2}]± A [{1,2,3}]±) Gl,G3,P,MP 
2.(-[{l, 2}]± A [{1, 2, 3}]1) D ([1 > 2 > 3 > 4]^ = [{1, 2}]^) Prop|l|.l 
3.7/; D ([1 > 2 > 3 > 4]<^ = [{1, 2}]ip) 1, 2, MP 

Thus, by epistemic reasoning in KD^, we have the results h ip D [0]{p A q) but 1/ 1/' 3 [0](r A s) when O = 1 > 
2 > 3 > 4. This means that both databases DB^ and DBj^ are discarded according to the ordering even only DB^ 
is in conflict with DBi and DB2- 

On the other hand, if the level skipping strategy is adopted. Then we have the following proof. 

I. 1/; D -[{1,2}]_L VZ 

2. V D ([{1 > 2, 3}]± = [{1, 2, 3}]±) 01', 1, P, MP 

3. V D ([{1 > 2,4}]± = [{1,2,4}]±) 01',1,P,MP 
4.1/; D [{1 > 2, 3}]_L yi, ^3, 2, P, MP 

5. V' D -[{1 > 2,4}]_L 3,P,MP 

6. [{1 > 2, 3}]± D ([{1 > 2 > 3, 4}]_L = [{1 > 2, 4}]_L) 02' 

7. V' D -[{1 > 2 > 3,4}]_L 4, 5, 6, P, MP 

8. ^ D ([{1 > 2, 4}]^ = [{1, 2, 4}]^) 1, 01', P, MP 

9. V' D ([{1 > 2 > 3, 4}](^ = [{1 > 2, 4}](^) 4, 02', P, MP 
10.1/' 3 ([1 > 2 > 3 > 4](^ EE [{1 > 2 > 3, 4}](^) 7, Ol', P, MP 

II. -0 D ([1 > 2 > 3 > 4](/3 = [{1,2,4}](^) 8, 9, 10, P, MP 

Thus we have \- "ip [0]{p Aq Ar A s) by epistemic logic, i.e. only DB^ is discarded for its conflict with DBi and 
DB2. □ 

The reasoning in the above example corresponds to the suspicious attitude in merging databases. In p5| , it 
is shown that the trusting attitude merging can also be simulated in the system DBF^, though the simulation is 
somewhat awkward. While the simulation in |^5| is restricted to the databases containing only literals, here we 
consider the general case. 

To simulate the trusting attitude merging, recall that for a partial order Q and the set Oq of all total orders 
compatible with it, [Q]'p is the abbreviation of AogOqI'^]'^- ^^'^ basic idea of the simulation is to split each 
database containing m wffs into m sub-databases, so we have in total X^iLi l^^il sub-databases. Let DBij denote 
the j-th sub-database obtained from the i-th database, then a total ordering O £ TOn is transformed into a partial 
ordering Q on the set XT) = {ij \ DBij is a sub-database} such that iiji > i2j2 in Q iff ii > 22 in O. Then the 
databases are represented by the following wff 

A ^^^^ A ^[G]^ 

ijeXV GeMCAG' 

where V'ij = A{[u]'/' I f G DBij} and MCAG' is the class of all maximal consistent agent subgroups of XI?. Thus, 
to decide whether ip is derivable from the merging of DBi , DB2 , • • • , DBn according to a total order O by the 
trusting attitude, we only have to do the following deduction in DBF^. 

The idea is illustrated in the following example. 

Example 2 Assume there are two databases DBi = {pVg} and DB2 = {^p, ~^q}, then according to the reasoning 
in DBFf, or DBF^, we have \- D {[I > 2]ip = [l]ip) , where = [l]{p V g) A [2]^p A [2]^q. Thus DB2 is completely 
discarded in the merging process. However, if we first split DB2 into two sub-databases DB21 = {^p} and 
DB22 = {^q} and let DBn = DBi, then we have \- ip' D ([Oi](^pV^g) A [02](^pV^g) where Oi = 11 > 21 > 22, 



02 = 11 > 22 > 21, and V' = [ll](p V g) A [21]^p A [22]-.g A -.[{11, 21}]_L A -[{11, 22}]± A -.[{21, 22}]_L. In other 
words, -.p V -iq will be derivable from the merging results according to the ordering 1 > 2 in the original databases. 
Note that here and -ip' are different wffs since they use different modal operators, though they essentially represent 
the same database contents. It must also be noted that the simulation is syntax-dependent since if the original 
second database is given as {-.p A ^q} which is equivalent to DB2, then we can not split it any more. □ 

5.2 Multi-agent epistemic reasoning 

Obviously, both DBFJ^ and DBF* are conservative extensions of KD^ in the sense that if we uniformly replace the 
modal operators Bi and Dq in a wff (p of KD^ by [i] and [G] respectively, then \=kd'^ V iff the replaced wff is valid 
in DBFJ^ or DBF^. Thus our systems can do all reasoning that KD^ can. Furthermore, if some additional axioms 
are added, we can turn our systems into conservative extensions of other epistemic logic systems. For example, if 
the following two axioms 4 and 5 are added, then our systems can do the reasoning of KD45^ system which is in 
general accepted as the logic for modelling agent's beliefs. 

4.[i](/?D [i\[{\ip 
5.-i[i]ip D [i]-.[«]v 

However, if an additional axiom T (called knowledge axiom): [i](p D tp is added to the above-extended system, then 
it will degenerate into the ordinary S5^ system in the sense that each wff [0](p is provably equivalent to [^(O)]^^ 
since no conflicts may exist if what every agent knows is true. In the following, let us look at some examples of 
integrated reasoning about the multi-agent beliefs and their fusion. 

Example 3 If a set of premises {-'[{1, 2}]-L V -[{1, 3}]_L, D q), [2]p, [3]^q} is given for three agents, then it 
can be derived that 

l-DBF^ [1 > 2 > 3]((p Aq)V A -g)) 

and 

^dbf;^ [l>2>3](pDg). 

The wff -i[{l,2}]_L V -i[{l,3}]± says that if the beliefs of agents 1 and 2 are incompatible, then those of 1 and 3 
are compatible, so the level skipping strategy will either accept the belief of agent 2 or skip it and consequently 
accept that of agent 3. This example shows that we can reason with the compatibility of the agents' beliefs in the 
uniform framework of epistemic reasoning and information fusion. □ 

The next example shows that the belief about belief may play a role in the fusion process. 

Example 4 Assume there are two agents whose beliefs arc described by the following set: 

{[l]-[{l,2}]±,[l]p, [l][l]p, [l][2]g 
[2][{l,2}]±,[2]q, [2][2]g, m]p} 

Then it can be shown that [1 > 2]p A [2 > l]q, [1][1 >2]{pAq)A [1][2 > l](p A g), and [2][1 > 2]p A [2] [2 > l]q are 
derivable in both DBF^ and DBF^. Thus the belief of agent 1 is incorrect because he wrongly believes that he is 
consistent with agent 2, while agent 2 in fact disagrees with him on the consistency between them.D 

Sometimes, it is possible to infer the beliefs of individual agents from their merged beliefs. The next example 
shows a very simple case. 

Example 5 Assume it is known that two premises [1 > 2]p and [2 > l]-.p hold, then we have the following 



derivation in DBF^ (where Pre in the derivation means a premise) 



1. -[{l,2}]±D([l>2]pD[{l,2}]p) 

2. ^[{1,2}]±D ([2> [{l,2}]-p) 

3. -[{l,2}]±D([{l,2}]pA[{l,2}]-p) 

4. ^[{1,2}]±D[{1,2}]± 

5. [{1,2}]± 

6. [l>2]pD [l]p 

7. [2 >l]^pD [2]^p 

8. [l]p 

9. [2]^p 

10. [l]pA [2]^p 



01 
01 

Pre, 1,2, P, MP 

3, P,Gl,MP,Gen 

4, P 



5, 02, MP 
5, 02, MP 
Pre, 6, MP 
Pre, 7, MP 
8, 9, P, MP 



When there are more than two agents, the situation would become more comphcated. However, it is still possible 
to derive some individual or partially merged beliefs from the totally merged ones.D 

A research area related to both epistemic logic and belief fusion is the modal logics for representing inconsistent 
beliefs. In an epistemic default logic is proposed for the representation of inconsistent beliefs caused by default 
reasoning. The logic is based on S5P developed in [s^ for modelling the monotonic part of default reasoning 

that deals with plausible assumptions. The basic modalities of S5P consist of an S5 epistemic operator K and a 
number of K45 belief operators Pi{l < i < n) . A wff Pi(p means that ip is a. plausible working belief according to 
some context or default rules. Since conflict between default rules is not unusual, it is possible that Pi(p A Pj^(p 
holds. Though Pi corresponds to an application context of some default rules, it can also be seen as the belief 
operator of some agent, so in this regard, the logic is like a multi-agent epistemic logic with an S5-based epistemic 
operator for the authority. However, instead of reasoning about the merging of different working beliefs in the logic 
directly, a downward reflection approach is adopted in |]55|| . Since the Pi operators are only applied to objective 
wffs in the downward reflection function maps a set of S5P wffs (especially wffs of the form Piip) into a set 
of non-modal formulas. Some downward reflection mechanisms are employed to resolve the inconsistency between 
working beliefs of different contexts. The one based on the explicit ordering on frames is essentially similar to 
our cautious merging. The main difference is that we take the orderings as modal operators and reason about 
the fusion results directly in the object language, while the downward reflection approach consider the fusion in a 
meta-level. 

5.3 Inconsistency handling in possibilistic logic 

In it is shown that the possibilistic logic approach to database fusion is very cautious, so a natural question 
is how the level cutting strategy is related with it. Here, we shown that the inconsistency handling technique of 
possibilistic logic can be modelled in the strategy. 

Possibilistic logic(PL) is proposed by Dubois and Prade for uncertainty reasoning ||2^, ^ The semantic 
basis of PL is the possibility theory developed by Zadeh from fuzzy set theory [fz^. Given a universe W, a possibility 
distribution on is a function tt : W ^ [0, !]■ Obviously, tt is a characteristic function of a fuzzy subset of W. 
Two measures on W can be derived from tt. They are called possibility and necessity measures and denoted by H 
and N respectively. Formally, H, N : 2^ [0, 1] are defined as 



{tp,a), where ip € >C($o) and a € (0,1] is a real number. The number a is called the valuation or weight of the 
formula, {ip, a) expresses that p is certain at least to degree a. Formally, a model for PLl is given by a possibility 
distribution tt on the set W of classical truth assignments for £($o)- For any p G £($o)j we can define \p\ as the 
set of truth assignments satisfying p . Then, by identifying ip and its truth set \(p\, a PLl model tt satisfies {p, a), 
denoted by tt ^ {p, a), if N{ip) > a. Let E = {{pi, ai) : 1 < i < m} be a finite set of PLl wffs, then E ^pli {p, a) 



I1{A) 



sup tt{w), 




if for each tt, tt ((p^, ai) for all 1 < z < 771 implies tt |= {ip, a). It is shown that the consequence relation in PLl 
can be determined completely by the least specific model satisfying S. That is, ii tts : W ^ [0, 1] is defined by 

7rE(w) = min{l — ai \ w \= -^ip, 1 < i < m}, 

where min0 = 1, then S ^pLi a) iff tts |= {ip, a). 

A special feature of PLl is its capability to cope with partial inconsistency. For E defined as above, let E* denote 
the set of classical formulas {f \ 1 < i < m}. Then the set E is said to be partially inconsistent when E* is classically 
inconsistent. It can be easily shown that E is partially inconsistent iff sup^g^7rs(w) < 1. Thus sup^g^ 7rs(?i') 
is called the consistency degree of E, denoted by Co7is(E), and 1 — Co7is(E) is called the inconsistency degree of 
E, denoted by /7t.co7is(E). When E is partially inconsistent, it can be shown that E |=pli {-L, I neons (T,)), so for 
any classical wff ip, [ip, InconsiT,)) is a trivial logical consequence of E. On the contrary, if E |=pli ct) for some 
a > InconsiY,), then Lp is called a nontrivial consequence of E. 

To model the nontrivial deduction of PLl, we assume that the weights of the wffs are drawn from a finite subset 
V = {ai, . . . , a„} of (0, 1]. Without loss of generality, we can assume ai > ■ ■ ■ > an- Let us define n databases 
from E as DBi = {ip \ {(p, ai) S E} for 1 < z < n. It can easily be seen that when each DBi is classically consistent, 
then for any ip e C{^o)i is a nontrivial consequence of E iff I^dbf^ V' D [1 > 2 > ■ • • > n\(p, where ip is the 
formula representing the databases. 



6 Incorporating Other Fusion Operators 

While we adopt a modal logic approach to belief fusion, there have been also a lot of works on knowledge merging 
by using meta-level operators]^, |[ ||, ^ |4^, 49, 5|, In the meta-level approach, a merging operator 

is in general used to combine a set of knowledge bases Ti,T2, ■ ■ ■ - Tk, where each knowledge base is a theory in 
some logical langauge. The main difference between our approach and theirs is that the belief fusion operators 
are incorporated into the object language in our logic, so we can reason not only with the merged results but also 
about the fusion process. However, the suspicious attitude used in our logic may be too cautious in some cases. 
Thus our logic should also be extended to accommodate these more sophisticated knowledge merging operators 
both syntactically and semantically. In the following, we will describe these operators briefly and discuss some 
possible extensions of our logic for incorporating them into the modal language. 

In the presentation below, we will extensively use the notions of pre-order. Let S" be a set, then a pre-order 
over S" is a reflexive and transitive binary relation < on S*. A pre-order over S is called total (or connected) if for 
all x,y € S, either x < y or y < x holds. We will write x < y as the abbreviation of x < y and y ^ x. For a subset 
S' of S, min(S", <) is defined as the set {x e S' \Wy e S', y x}. 



6.1 Combination by maximal consistency 

One of the earliest approaches to knowledge merging is to manipulate the maximal consistent subsets of the union 
of the component databases. In |§, |^, knowledge bases with integrity constraints are combined by a meta-level 
combination operator to form a new knowledge base. While in ^, logic programs and default logic theories are 
considered which have different semantics than the classical logic, the basic idea for combining first-order theories 
in Q can be carried out in our logic. In [Q, a combination operator C maps a set of knowledge bases {Ti, ■ ■ ■ ,Tk} 
and a set of integrity constraints IC into a new knowledge base C{Ti, ■ ■ ■ ,Tk, IC) which can be roughly considered 
as the disjunction of maximally consistent subsets of Ti U T2 U • • • U with respect to IC. 

Unlike our fusion operators which correspond to total orders on the agents, the combination operator assumes 
all knowledge bases are equally important, so there are no priorities among them, though the priority is obviously 
given to the integrity constraints. Therefore, by using the partial order fusion operators, we can analogously model 
the combination operator in our logic. Let us consider n agents where the belief of agent 1 is the set IC and each 
sentence in Ti U r2 U • ■ • U is exactly represented as the belief of one agent in {2, ■ • ■ , n}, then for the partial order 
Q = {1 > 2, 1 > 3, • • • , 1 > n}, the modal operator [Q] can produce the same result as the combination operator C. 
Note that just like the simulation of trusting attitude multi-sources reasoning in our logic, the maximally consistent 
combination is also syntax-dependent. 

In ]4l| , it is argued that the maximally consistent combination lacks many desirable properties of knowledge 
merging. This is due to the fact that the source of information is lost in the combination process. Some im- 
provements based on the selection of some maximally consistent subsets instead of all ones are then proposed to 



circumvent the problem. Three approaches are suggested according to the difference of the selection functions. 
The first selects from the set of maximally consistent subsets those consistent with the most knowledge bases, the 
second selects those that have least difference (in terms of number of sentences) with the knowledge bases, and the 
third selects those that fit the knowledge bases on a maximum number of sentences. Though these improvements 
indeed satisfy the desirable logical properties argued by the author, they are all syntactical operator and lack a 
model-theoretic semantic characterization. Furthermore, since the second and the third improvements are based 
on the comparison of cardinalities of sets of wffs, they works only for finite knowledge bases. This makes it difficult 
to incorporate these improved combination operators into our logic where each agent's beliefs are closed under 
logical consequence. Fortunately, there are other elegant merging operators with the desirable logical properties 
which can be incorporated into our framework, so we will consider some of them in the following sections. 

Yet another syntax-based approach is to remove the wffs causing inconsistency. In , this approach is explored 
when only local ordering between the wffs is given. However, the approach is more algorithmic and it seems not 
appropriate to incorporate it into our framework. 

6.2 Combination by meta-information 

In the combination by maximal consistency, it is assumed that no information about how to combine the knowledge 
bases is available. However, sometimes the users can provide valuable meta-information about the combination 
process, such as the reliability of the component databases, the user's preference, or the interaction of different 
databases, etc. In [^^, a kind of priorities between sets of propositional atoms is represented and the combination 
is made according to the prioritized information. In fact, our fusion operators (either total orders or partial ones) 
also encode a kind of priorities. The main difference is that our priorities are between agents while theirs are 
between the sets of propositions believed by the agents. However, since transitivity is not required for the priority 
relation in |]58| , there may exist cyclic priorities (i.e., x > y and y > x holds simultaneously). In such cases, there 
would not be combined knowledge bases satisfying the priorities. Furthermore, since the knowledge bases in 
are just sets of propositional atoms, the approach applies only to deduction-free relational databases and lacks the 
capability of reasoning about the inter-relationship between the knowledge bases. 

A more flexible way for specifying the meta-information is proposed in |Q . In that work, a set of local databases 
DBi, • • • , DBn is combined with a supervisory knowledge base S. Intuitively, S contains conflict resolution infor- 
mation. Since the databases are expressed in a very rich language, the supervisory knowledge base can specify 
complex relations between local databases. The language is called annotated logic and is constructed from some 
base language and a set of annotations. These annotations can denote the truth values for many-valued logic, 
timestamps, uncertainties, etc., so the expressive power of annotated logic is quite rich. In the framework, the 
local databases are just sets of sentences in the annotated logic, whereas the supervisory knowledge base contains 
sentences in another annotated logic where each atom is indexed by a subset of {1, 2, • • • , n, s}. 

To compare the framework in [ |68[ with our logic, let us assume the only annotations are the classical truth 
values {t,f}, so the annotated logic reduces to the classical one. In this simplifled case, the annotations can be 
simply removed and each local database contains logic program clauses of the form 

Pa ^ Pi,-- - ,Prn, not|5„j+i, ■ • • , notp,n+k 

where for all < i < m -I- /c, is an atomic formula in classical logic, whereas the supervisory knowledge base S 
contains indexed clauses of the form 

Pa : {s} ^ pi : Di, - ■ ■ ,pm ■■ Dm, not(p„+i : Dm+i), • • • , not(p,„+fe : D„i+k) (2) 

where for all 1 < i < to + fc, Di C {1, 2, • • • , n, s}. The intended meaning oi p : Di is that the databases in Di 
jointly say that p is true. The meaning is specified by a combination axiom scheme which is equivalent to 

p-.D^ \J p-.D' (3) 

0C-D'C-D 

in our simplified case. For each local data base DBi, the amalgamation transform of DBi, AT{DBi), is defined as 
the result of replacing each clause po <— pi, - ■ ■ ,Pm,, notpm+i, • • • , notpm+k in DBi by 



Po ■ {i} ^ Pi ■ {i},---,Pm ■ {i},not{p„i+i : {i}), ■ ■ ■ ,not{pm+k ■ {«}) 



(4) 



Consequently, the amalgam of {DBi^ . . . , DB^^ S) is defined as the amalgamated knowledge base 

n 

Su[j AT{DBi) U Combination axioms 

i=l 

Though the semantics of the amalgamated knowledge base is given according to that of logic program, so not 
comparable with that of classical logic. However, the idea of supervisory knowledge base can be easily realized in 
the multi-agent epistemic logic (and so in our logic). In fact, the clause in can be translated into our logic as 

l<i<m rii-\-l<i<'m-\-k 

whereas the combination axiom (|^) is a special case of the axioms G3 or V3 in our systems. Though the annotated 
logic provides a far richer expressive power in the representation of objective knowledge than our systems and the 
supervisory knowledge base can express conflict resolution information among local databases, the framework in 
[ |68| still lacks the capability of reasoning about mutual information. Contrarily, each agent can easily reason about 
the beliefs of other agents in our logic. For example, it is possible to say that agent i believes that if agent j believes 
(f, then agent k would also do. This somewhat reflects the essential difference between the modal logic approach 
and the meta-level ones to the belief fusion. 



6.3 Merging by majority 

Though the maximal consistent combination resolves the conflicts between knowledge bases, it does not reflect the 
view of the majority. For example, if three knowledge bases Ti = T2 = {(f}, and T3 = {^(p} are combined 
by the maximal consistent combination rule, the result would be just a knowledge base containing the tautology. 
However, if the majority view is taken into account, then the result would be {tp}. In ]4^ , a merging operator 
reflecting the views of majority is proposed for knowledge bases consisting of finite propositional sentences. Since 
the propositional language is assumed finite there, the so-called Dalai distance between two interpretations of the 
language is used[^. It is defined as the number of atoms whose valuations differs in the two interpretations. Let 
dist{w,w') denote the Dalai distance between two interpretations w and w', then the distance from w to a theory 
T, denoted by dist{w, T), is defined as 

dist{w,T) — min{dist{w,w') \ w' ^ T}. (5) 

Given a set of knowledge bases Ti, T2, • • • , to be merged, a total pre-order ^{ri,T2,---,Tfc} is defined on the set of 
interpretations by 

k k 

''^ ^{Ti,T2,---.Tk} ^' ''^^dist{w,Ti) <''^^dist{w' ,Ti) (6) 

i=l i=l 

Then the merged result Merge{Ti,T2, ■ ■ ■ ,Ti^) is the theory whose models are all interpretations minimal with 
respect to the order ^{Ti,r2,- -,rfc}- 

In a set of postulates for characterizing the merging function is presented and its corresponding model- 
theoretic characterization is also given. It is then shown that Merge is indeed a function satisfying the postulates. 
In |4|], the function Merge is further generalized for the application in weighted knowledge bases. Let wt : 
{Ti, T2, • • • , Tfc} i?+ is a weight function which assigns to each component knowledge base a positive real 
number, then the total pre-order in (^) is changed into 

k k 

w d:({Ti,T2,---,Tk},wt) w' iff '^dist{w,Ti) ■ wt{Ti) <'^dist{w' ,Ti) ■ wtiTi) (7) 

i=l 1=1 

Then the merged result Merge(Ti, T2, ■ ■ ■ ,Tk, wt) is the theory whose models are all interpretations minimal with 
respect to the order :<({Ti,T2,---,Tk}:Wt)- 

Since the weighted version of the merging function is more general, we will consider the extension of our logic for 
the weighted merging operator. First, a new class of modal operators [M{G, wt)] for any nonempty G C {1, 2, • • • , n} 



and weight function wt : G ^ i?+ is added to our logic language. Then the semantics for the new modal operators 
is defined by extending a possible world model to {W,{TZi)i<i<n,V,fi), where {W, {TZi)i<i<n,V) is a DBF^ (or 
DBFfj) model, whereas ij. : W x W i?+ U {0} is a distance metric function between possible worlds satisfying 
//(w, w) = and w') — w). 

It must be noted that our possible worlds are more than the truth assignments of the propositional symbols, so 
it is inappropriate to define the distance between two possible worlds by merely enumerating the number of atoms 
whose valuations differs in the two worlds. However, it is assumed a distance metric between possible worlds can 
be defined just as in the semantics of conditional logic ||57|, |62| . To give the semantics of the new operators, we first 
define the distance from a possible world w to the belief state of an agent i in the possible world u by 

distu{w,i) = mi{^{w,w') \ {u,w') ElZi}. (8) 

Then a total pre-order ^^g, on the possible worlds is defined for each possible world u and modal operator 

[M{G, wt)] 

wd^^Gwt)''^' '^^distu{w,i) ■ wt{i) <'^^distu['w' ,i) ■ wt{i). (9) 

The most straightforward definition for the satisfaction of the wff [M{G, wt)]if is 

u ^ [M{G,wt)]tf iff for all w e 7^Af(G,toi) ^« h 

where TlM(G,wt) is a binary relation over the possible worlds such that TZM{G,wt){u) = min(VF, ^"g, ^^^). However, 
since for infinite W, the set min(VF, ^"g, ^^j) may be empty, the definition may result in u |= [M{G, wt)]l. in some 
cases. Alternatively, since ^"g, is a total pre-order, it is just like the a system-of-spheres in the semantics of 
conditional logic jSTf, so we can define the satisfaction of the wff [M{G, wt)]ip by 

u ^ [M (G, wt)]Lp iff there exists Wq such that for all w :<^q wojW ^ (f- 

An alternative approach to do majority merging is to employ the graded modal logic in js^, |9|. In the logic, 
a set of modal operators Km, where m is a natural number, is in place of the ordinary epistemic or doxastic 
operators. In the single agent case, a modal formula K^f means that in all possible worlds the agent considers 
possible, there are at most m worlds at which ip is false. By the abbreviations, Mmf = -^Km^'P, Mloip = Ko^ip, 
and Mljn^ = {Mm-iP> A ^Mm(^), it can be seen that Ml^T A K^^^ (p means the wff ip is true at more than half of 
the worlds. By generalizing this kind of graded modal operators for distributed belief fusion, we can consider the 
modal operators [G]r for any real number r and subset of agents G. The semantics for [G]rP is interpreted in the 
multi-agent epistemic logic model such that 



w 



h [G]rP iff l{"H'^l"euieGK,(to)}| ^ 



Then [G]c for some threshold c > 0.5 can be taken as the fusion operator which merges the beliefs of agents in 
G. However, it must be noted that the majority considered in the graded modal logic is the majority of possible 
worlds instead of that of agents. Furthermore, by using the cardinality of sets of possible worlds in the definition, 
the semantic models are restricted to finite ones. To lift the restriction, some numerical measures, such as the 
probability, should be added to the models. 



6.4 Arbitration 

The notion of distance measure between possible worlds is also used in another type of merging operator, called 
arbitration p6| |60| . Arbitration is the process of settling a conflict between two or more persons. The first version 
of arbitration operator between knowledge bases is proposed in via the so-called model-fitting operators. The 
postulates for model-fitting operators and its semantic characterization are given and then arbitration is defined 
as a special kind of model-fitting operators. 

In iQ, the arbitration operator is further generalized so that it is applicable to the weighted knowledge bases. 
A set of postulates is also directly used in characterizing the arbitration between a weighted knowledge base and 
a regular one. A weighted knowledge base in ||60|| is defined as a mapping K from model sets to nonnegative real 
number and a regular knowledge base is just a finite set of propositional sentences. A generalized loyal assignment 



C <AuB D and A <c B or 
D <AuB C and A <d B 



is then defined as a function that assigns for each weighted knowledge base K a pre-order < between propositional 
sentences such that some conditions are satisfied for the pre-orders. Finally, the arbitration of a weighted knowledge 
base K hy a regular knowledge base K' is defined as 

XAX' = min(A",<^,), 

where Tnh\{K\ <f.) is the set of sentences in K' which is minimal according to the ordering <^. However, this 
kind of arbitration is obviously syntax-dependent. For example, if and (f2 is two propositional sentences such 
that ipi <f^ (p2, then KA{(pi, V2} = Wi} 7^ KA{ipi A ip2} = {vi ^ ¥'2} though the two knowledge bases {ipi, 1P2} 
and {ipi A (^2} are semantically equivalent. 

An alternative, seemingly more natural, characterization for arbitration is given in p6| without resorting to the 
model-fitting operators. A knowledge base in that work is identified with the set of propositional models for it, 
thus the semantic characterization for this kind of arbitration is given by assigning to each subset of models A a 
binary relation <a over the set of model sets satisfying the following conditions (the subscript is omitted when it 
means all binary relations of the form <a) 

1. transitivity: if A < B and B < C then A <C 

2. HACB then B <A 

3. A < AU B and B < AU B 

4. B <aC for every C iff ^ n B 7^ 

5. A <cuD B ^ 

Then the arbitration between two sets of models A and B is defined as 

AAB = min(A, <b) U min{B, <a) (10) 

Note that though the relation <a is defined between sets of models, in the definition of the arbitration, only <a 
between singletons is used. Thus by slightly abusing the notation, <a may also denote an ordering between models. 

To incorporate the arbitration operator of into our langauge, we must first note that according to (|l^), the 
arbitration is commutative but not necessarily associative. Thus, the arbitration operator should be a binary one 
between two agents. We can add a class of modal operators for arbitration into our logic just as in the case of 
majority merging. However, to be more expressive, we will also consider the interaction between arbitration and 
other epistemic operators, so we define the set of arbitration expressions over the agents recursively as the smallest 
set containing {1, 2, • • • , n} and closed under the binary operators •, and A. Here -I- and • correspond respectively 
to the distributed belief and the so-called "everybody knows" operators in multi-agent epistemic logic Then our 
language can be extended to include a new class of modal operators [a] where a is an arbitration expressions. Note 
that it has been shown that the only associative arbitration satisfying postulates 7 and 8 of [|6| is AAB = AU B, 
so if A is an associative arbitration satisfying those postulates, then [aA6](y5 is reduced to [a ■ b]ip which is in turn 
equivalent to [a\ip A [b]ip. 

For the semantics, a model is extended to {W, {TZi)i<i<n,V, <), where {W, {TZi)i<i<n,V) is a DBF^ (or DBF^) 
model, whereas < is a function assigning to each subset of possible worlds A a binary relation <aQ 2^ x 2^ 
satisfying the above-mentioned five conditions. Note that the first two conditions imply that <a is a pre-order 
over 2^. Then for each arbitration expression, we can define the binary relations TZaAb,Ti-a b and TZa+b over W 
recursively by 

TlaAbiw) = min(7^a(w), <K5(u.)) U min(7^6(w), <k„(u,)) (11) 

Ha+b --Uannb (12) 
TZa.b = 7^a U 7^fc (13) 

Thus the satisfaction for the wff [a](p is defined as 

u \= [a\ip iff for all w e TZa{u),w \= ip. 

Note that the distributed belief operator [G] can be equivalently defined as an abbreviation of [ii + (z2 + • • • {ik~i + 
ik))] if G = {ii,i2, • • ■ ,ik}- 

By this kind of modal operators, the postulates 2-8 of |Bq| can be translated into the following axioms: 



1. [aAb]^ = [bAa]ip 



2. [aAb]Lp D [a + b]Lp 

3. -.[a + b]l. D {[a + b]ip D [aAb](p) 

4. [aAb]± D [a]±A[b]± 

5. ([aA{b ■ c)]ip = [aAb]Lp) V ([aA{b ■ c)]ip = [aAc](p) V ([aA{b ■ c)]ip = [{aAb) ■ {aAc)](p) 

6. [a]tp A [b]ip D [aAb]ip 

7. -[a]_L D ^[a+ (aA6)]± 

However, since the set of possible worlds W may be infinite in our logic, the minimal models in (|ll|) may not 
exist, so the axioms 4 and 7 are not sound with respect to the semantics. To make them sound, we must add the 
following limit assumption]^ to the binary relations <a for any A C W: 

for any nonempty U QW, min(C/, <y!i) is nonempty. 

It must be noted that the axioms listed above are not yet complete for the logic with arbitration operators. In fact, 
the search of a complete axiomatization for the modal logic of arbitration expressions is of independent interest 
by itself and can be the further research direction. The brief presentation here just shows that the modal logic 
approach can provides a uniform framework for integrating the epistemic reasoning and different knowledge merging 
operators into the object logic level. 



6.5 General merging 

In ]4^ , an axiomatic framework unifying the majority merging and arbitration operators is presented. A set 
of postulates common to majority and arbitration operators is first proposed to characterize the general merging 
operators and then additional postulates for differentiating these two are considered respectively. In the framework, 
a knowledge base is also a finite set of propositional sentences. The general merging operator is defined as a mapping 
from a multi-set (also called a bag)^ of knowledge base (called a knowledge set) to a knowledge base. Thus the 
arbitration operator defined via the approach can merge more than two knowledge bases whereas the arbitration 
operator in [46) is defined only for two knowledge bases. The merging operator is denoted by A, so for each 
knowledge set E, A{E) is a knowledge base. Two equivalent semantic characterizations are also given for the 
merging operators. One of them is based on the so-called syncretic assignment. A syncretic assignment maps 
each knowledge set i? to a pre-order <e over interpretations such that some conditions refiecting the postulated 
properties of the merging operators must be satisfied. Then A{E) is the knowledge base whose models are the 
minimal interpretations according to <e- 

This logical framework is further extended to dealing with integrity constraints in ]4^ . Let be a knowledge 
set and is a propositional sentence denoting the integrity constraints, then the merging of knowledge bases in E 
with integrity constraint ip, Ai^[E), is a knowledge base which implies Lp. The models of A^p{E) is characterized 
by min(Mo(i((/j), <_b), i.e., the minimal models of ip with respect to the ordering <e- Aip{E) is called IC merging 
operator. According to the semantics, it is obvious that A{E) is a special case of IC merging operator At(-E)- 
It is also shown that when E contains exactly one knowledge base, the operator is reduced to the AGM revision 
operator proposed in [Q. Thus IC merging is general enough to covering the majority merging, arbitration and 
AGM revision operator. 

To realize the IC merging operators in the modal logic framework, we will extend the syntax of our logic with 
the following formation rule: 

• ii ip and ip are wfFs, then for any nonempty G C {1,2,..., n}, [A^{G)]ip is also a wfF. 

For the naming convenience, we will call a subset of possible worlds a belief state. Let U — {Ui, U2, ■ ■ ■ , Uk} denote 
a multi-set of belief states, then f]U ~ Ui Ci ■ ■ ■ Uk- For the semantics, a possible world model is extended to 
{W, {TZi)i<i<n,V, <), where {W, {TZi)i<i<n,V) is a DBF^^ (or DBF^) model, whereas < is an assignment mapping 
each multi-set of belief states U to a total pre-order <u over W satisfying the following conditions: 

*A multi-set (or bag) is a collection of elements over some domain which allows multiple occurrences of elements. 



1. If w,w' e{~\U, then w <u w' 



2. If w e fl ^ and w' ^ f| W then w <u w' 

3. For any w Cz Ui, there exists w' E U2, such that w' <{Ui,U2} ''^j where Ui and U2 are two behef states 

4. If w w' and w w' , then w <UiuU2 ""^'i where U denotes the union of two muhi-sets 

5. If u> w' and w w' , then w <Uiuu-i w' 

For a sub-group of agents G and a possible world u, let us define a total pre-order <q over W as follows: 

W <G w' iff W <{Ki{u)\ieG} w'. 

Then a possible world u satisfies the wff [A;p(G)]?/' in the model, i.e. u \= [A^(G)]V', iff 

(i) there are no possible worlds in W satisfying or 

(ii) there exists wq €W such that wo H <^ and for any w <^ Wi), w \= Lp if}. 

Though we can incorporate the general merging operator into the modal logic framework, we should not overlook 
the difference between the meta- level merging operators and the modal ones. First, in the meta- level approach, 
the knowledge set consists of a multi-set of objective sentences, whereas in the modal operator [A^(G')], G is a set 
of agents whose belief may contains subjective sentences or beliefs of other agents. Second, the integrity constraint 
can only be the objective sentences in | |4^ whereas may be arbitrary complex wff of our extended language. 
Finally, instead of selecting the minimal models from those of since the set of possible worlds may be infinite in 
our case, we adopt the system-of-spheres semantics as that in section |6.3| for the modal operator [A;^(G)]. 



7 Belief Change and Conditional Logic 

7.1 Incorporating belief revision operators 

Unlike knowledge merging, where the component knowledge bases are equally important, belief change is a kind of 
asymmetry operators, where the new information always outweighs the old one. The main belief change operators 
are belief revision and update. They are characterized by different postulates 39 1. In a uniform 



model-theoretic framework is provided for the semantic characterization of the revision and update operators. In 
their works, a knowledge base is a finite set of propositional sentences, so it can also be represented by a single 
sentence(i.e., the conjunction of all sentences in the knowledge base). 

For the revision operator, it is assumed that there is a total pre-order <^ over the propositional interpretations 
for each knowledge base ■(/'• The revision operators satisfying the AGM postulates in |^ are exactly those that 
select from the models of the new information ip the minimal ones with respect to the ordering <^. More precisely, 
let tp he & knowledge base and ip denote the new information, then the result of revising -0 by (p, denoted hy %p o Lp^ 
will have the set of models 

Modiip o tp) ~ min{M od{ip) , <^). 

As for the update operator, assume for each propositional interpretation w, there exists some partial pre-order 
<u} over the interpretations for closeness to w, then update operators select for each model w in Mod{^p) the set of 
models from Mod{(p) that are closest to w. The updated theory is characterized by the union of all such models. 
That is, 

Mod{il}Oip) ^ y Tmn{Mod{ip),<.u]) 

weMod{ip) 

where o is the result of updating the knowledge base "0 by p. 

Both belief revision and update may occur in the observation of the new information ip. For the belief revision, 
it is assumed that the world is static, so if the new information is incompatible with the agent's original beliefs, 
then the agent may have wrong belief about the world. Thus he will try to accommodate the new information by 
minimally changing his original beliefs. However, for the belief update, it is assumed that the observation may be 
due to the dynamic change of the outside world, so the agent's belief may be out-of-date, though it may be totally 



correct for the original world. Thus the agent will assume the possible worlds are those resulting from the minimal 
change of the original world. In [ p^ , a generalized update model is proposed which combines aspects of revision 
and update. It is shown that a belief update model will be inadequate without modelling the dynamic aspect (i.e. 
the events causing the update) in the same time. Since the dynamic change of the external worlds does not play 
a role in the belief fusion process, we would not try to model the belief update in our logic, so in what follows, we 
will concentrate on the belief revision operator. 

Let us now consider the possibility of incorporating the belief revision operator into our logic. In addition to 
the original meaning of revising a knowledge base by new information ip, there is an alternative reading for the 
revision operator. That is, we can consider o as a prioritized belief fusion operator which gives the priority to its 
second argument |37| . In the context of knowledge base revision, these two interpretations are essentially equivalent. 
However, from the perspective of our logic in multi-agents systems, they may be quite different. Roughly speaking, 
i o ip will denote the result of revising the beliefs of agent i by new information ip, whereas i o j is the result of 
merging the beliefs of agents i and j by giving priority to j. More formally, an revision expression will be defined 
inductively as follows: 

• li I < i, j < n and 1^9 is a wff, then i o j and i o ip are revision expressions. 

• If r is a revision expression, 1 < i < n and ip is a wff, then r o i and r o ip are revision expressions. 

The syntactic rule is extended to include the modal operators [r] for any revision expression r, so [r]ip would be 
a wff if ip is. To interpret the modal operator in our semantic framework, a possible world model is extended to 
{W, {TZi)i<i<n,V, <), where {W, {1^1)1 <i<n,V) is a DBF^^ (or DBF^) model, whereas < is an assignment mapping 
each belief state (i.e. subset of possible worlds) [/ to a total pre-order <[/ over W such that (i) if w,w' G U, then 
w <u w' and (ii) ii w G U and w' ^ U, then w <u w' . Let S ■ U denote the sequence (C/i, U2, • • ■ , J7fc, U) if 
S = [Ui, U2, • • • , Uk) is a sequence of belief state, then the assignment < is extended to sequences of belief states 
in the following way (we assume <(u)—^u)- 

1. w <s u w' if w £ U and w' ^ U 

2. w <s u w' iff w <s w' when w,w' G U or w,w' ^ U 

For each wff if, let the truth set of ip, denoted by \ip\, be defined a,s {w G W \ w \^ if}. For each possible world u, 
define a function mapping any agent i and revision expression r into a sequence of belief states u{i) and u{r) as 
follows: 

1. u{i) = {TZ.,{u)) 

2. u(r o i) — u{r) ■ TZi{u) 

3. u{r o ip) — u{r) ■ \ip\ 

Then the truth condition for the wff [r o ip]ip is u \^ [r o ipj-ip iS 

(i) there are no possible worlds in W satisfying ip, or 

(ii) there exists wq G W such that wq \^ ip and for any w <u(r) wq, w \^ ip D ip. 

Analogously, u \^ [r o iff there exists wq e TZi{u) such that for any w <u(r) wq, if w G TZi{u), then w ^ ?/'• It 



can be seen that [i o ip]ijj is equivalent to [A^{{i})]'il} in section 3.5 according to the semantics 



7.2 Relationship with conditional logic 

There have been also various attempts in formalizing the belief change process by modal logic or conditional logic 
systems^, ^ 33, |6^, For example, in ||l^, a modal logic CO* is proposed for modelling the belief 



revision. CO* is an extension of the logic CO proposed in g. In CO*, revision of a theory by a sentence is 
represented using a conditional connective. The connective is not primitive, but rather defined using two unary 
modal operators □ and □ . The modal operators are interpreted with respect to a total pre-order R over the possible 
worlds which is assumed to rely on a background theory K. Thus w \= Oip iff ip is true in all possible worlds which 



are as plausible as w given the theory K and w iff is true in all possible worlds which are less plausible 

than w given K. By defining □ as Oip/\ □ ip and O as □ -,ip^ the conditional (p ^ ip is defined as 

□ -,(^V O {(pAD{ip D V)), 

where KB is a finite representation of the theory K. Since there is only one global ordering R in CO* model 
which is associated with the background theory, the logic is appropriate only for reasoning about the revision of a 
single theory K. On the other hand, our logic allows the reasoning about revisions of many agents' belief states. 
Furthermore, since the ordering R in CO* model is global, ip ^ ip is true in a world iff it is true in all worlds, 
thus no iterated revisions are allowed in the model. In , this restriction is lifted by allowing the revision of the 
ordering R to R' at the same time. The idea is to move the most plausible (^-models with respect to R to the most 
plausible level of R' and keep the other parts of R unchanged. Our assignment of a total pre-order to a sequence 
of belief states is basically based on the same idea. However, while the definition of presumes the existence of 
the minimal models for any propositional formulas, we do not need such assumption. 

In , a logic with conditional and epistemic operators is used in the reasoning of belief revision. The condi- 
tional and epistemic sentences are interpreted in an abstract belief change system (BCS). The basic components of 
a BCS are a set of belief states and a belief change function mapping each belief state and sentence of some base 
language into a new belief state. In a more concrete preferential interpretation, each belief state s is interpreted as 
a subset of possible world K{s) and a pre-order <s over the possible worlds is associated with it. In this regard, 
■<s corresponds to ^k{s) in our semantic models and the conditional wff ip > ip va the logic of [ p3| is roughly 
equivalent to our wff [i o for some fixed agent i. However, since in the antecedent (p oi a, conditional is 
restricted to a wff in the base language C, it does not allow the epistemic wffs of the form Bip. It is argued that the 
antecedent must be observable whereas conditional wffs are unobservable, so we should not allow conditional wffs 
in the antecedent. However, from the multi-agent systems perspective, one agent may learn the beliefs of other 
agents by communication, so we should not exclude the flexibility. Another significant difference is that the BCS 
allows only revision of a belief state by a sentence, while in our system, the prioritized fusion of two belief states 
held by two agents are also incorporated. 

A dynamic doxastic logic for belief revision is proposed in |]6^ and further developed in p^ . By using the 
notations of |]63| , the doxastic operator B and two kinds of dynamic modal operators [-l-<^] and [— tp] for propositional 
wff ip are taken as the basic constructs of the language. The operators [-\-p\ and [—</?] corresponds respectively to 
the expansion and contraction operators in AGM theory. Thus the revision operator [otp] is defined as [—(^V')] [+'/'] 
according to the so-called Levi's identity[Q. The wffs of the language are interpreted with respect to a hypertheory. 
A hypertheory H is a, set of subsets of possible worlds linearly ordered by inclusion. A hypertheory is similar to 
the widening ranked model defined in [Q. However, the latter assumes that the subsets of models are indexed 
by natural numbers. A hypertheory is said to be replete if the set of all possible worlds W is in H . From the 
hypertheory H , a pre-order <h over W can be defined as follows: 

w' <H "iw iff for any U E H, ii w £ U, then there exists U' £ H such that U' C U and w' E U' . 

When H is replete, the pre-order defined in this way is total. When the wffs [-l-</?]V' and [— (^cji/' are evaluated 
with respect to a hypertheory H, it causes evaluation of ip in some revised hypertheory H' , so the semantics are 
essentially equivalent to that proposed in , though the revisions of the corresponding pre-order are somewhat 
different in the two approaches. Therefore, as the proposal of [Q, the logic allows only reasoning about the belief 
revision of a single agent by some new information and the prioritized fusion of multi-agent beliefs can not be 
represented in such logic. 



7.3 Alternative representations of belief states 

In our presentation above, we assume an agent's belief states are represented as a subset of possible worlds, i.e. 
TZi(w) is the belief state of agent i in world w. However, some more fine-grained representations have been also 
proposed, such as total pre-orders over the set of possible worlds |2^, ordinal conditional functions 

[p^ |6^ , |70t| , possibility distributions 0, |9|, |o), belief functions Q and pedigreed belief states Perhaps, the 
most popular representation among them is an ordering of the possible worlds. While a set of possible worlds can 
be seen as the minimal worlds with respect to a given ordering, it is claimed that the fusion of two orderings is 
more general than the revision of an ordering by a set of possible worlds]^. Thus it is shown that AGM revision 



is in fact a special case of the fusion operator in Indeed, in our extended models, the assignment < has 

mapped each subset of possible worlds to a total pre-orders between worlds. However, to fully utilize the semantic 
power of an ordering, the logic language should be extended further to cover the conditional connectives. Since the 
purpose of the present paper is to integrate the belief fusion operators into the epistemic reasoning framework, this 
extension is beyond its scope. Nevertheless, the further development of logical systems incorporating the fusion 
operators based on fine-grained representations of belief states should be a very interesting research direction. 



8 Conclusions and Further Researches 

The main contribution of the paper is the integration of belief fusion operators into the multi-agent epistemic logic. 
We first propose two basic logical systems for reasoning about the cautiously merged beliefs of multiple agents and 
then extend them to cover more sophisticated and adventurous fusion and revision operators. 

The basic systems are cautious in the sense that if an information source is in conflict with other more reliable 
ones, then the information from that source is totally discarded. The two systems correspond to two different 
strategies of discarding the information sources. For level cutting strategy, if an information source is to be 
discarded, then all those less reliable than it are also discarded without further examination. On the other hand, 
for level skipping strategy, only the level under conflict is skipped, and the next level will be considered independent 
of those discarded before it. Thus, level skipping strategy is relatively less cautious than the level cutting one and 
indeed, we can simulate the trusting attitude multi-sources reasoning in jl^ by level skipping strategy. 

Then some of the most important knowledge base merging approaches are reviewed and it is shown that many 
fusion operators proposed in those approaches can be incorporated into our logic. While most of the knowledge 
base merging research takes the fusion process as a meta-level operator, our approach incorporate them into the 
object logic directly. Therefore, it is possible to integrate the belief fusion operators into the multi-agent epistemic 
logic. What we can benefit from the epistemic logic is the capability to reasoning with not only the beliefs about 
the objective world but also the beliefs about beliefs. 

In the discussion of the belief fusion logic, for simplicity, we do not distinguish belief and information. However, 
in a genuine agent systems, an agent's belief may be different than the information he sends to or receives from 
other agents. Thus, in general, we should have a set of modal operators such that [j]iip means that agent 
i receives the information ip from j. In particular, [i\iip may represent the observation of agent i himself, which 
should be the most reliable information source for i. Then agent i may form his belief by fusing the information 
he received from different agents according to the degrees of trust he has on other agents. The fusion may be 
represented by the operators [0]i. If we consider [j]iip as the communication of message if from j to i, then we 
have a general framework for reasoning about agent's belief and communication. In such a framework, we can 
discuss the problems like deception of agent. For example, [0]i</5 A [i]j^<;5 may mean that agent i deceives to agent 
j by telling j the negation of what he believes. In |2l|| , an application of our basic systems to reasoning about 
beliefs and trusts of multiple agents has been proposed along this direction. However, more works remain to be 
done for the real applications. These applications may also benefit from some fundamental works on multi-agent 
belief revision || ^ ||, ||, 0. 

From a more foundational viewpoint, though we have proposed some extensions of the basic systems for ac- 
commodating the belief fusion operators both syntactically and semantically, the complete axiomatization of these 
extended logics remain to be found. To be practically useful, other proof methods more suitable for automated 
theorem proving should be also developed. 

In a recent paper, it is shown that the multi-sources reasoning can be applied to deontic logic under conflicting 



regulations! 17 . Essentially, this is to merge conflicting regulations according to the priorities of them analogously 
to the fusion of information. However, inherited from the restriction of FU„, it is also required that each regulation 
to be merged must be a set of deontic literals. Now, by the systems developed here, it is expected that the general 
forms of regulations can also be merged. 

A real difficulty in the application of our logic to model the database merging reasoning is the representational 
problem of the databases. In the discussion of section ||, we suggest to find all maximal consistent agent groups 
in advance and add the wff /y^gj^^p^g ^[G]_L to the representation. This is a rather time-consuming work. In 
practice, we can omit this part and check the consistency of some agent groups when it is necessary during the 
course of proof. Even further, we can consider the implementation of the logic with some non-monotonic reasoning 
techniques P| so that only the explicit information in the databases have to be represented by the wffs. This will 



be investigated in the further research. 
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A Proof of the Proposition and Theorems 
A.l Proof of Proposition |1] 

1. By induction on m — \6(0')\: 

m = 1: this is trivial since we identify [ii\ip and [{«i}]'/? in our language, 
assume this result holds for all m < k. 
m = fc + 1: there are two cases: 



j = m; I — ^[Gj](^ D {[0]ip = [Gj]ip) is just an instance of axiom 01, 

j < m: let O be written as O' > im where O' = ii > . . . > ik, then this proof is as follows: 

1. ^[Gj]± A [G,+i]± D [G™]± G3,m>j + 1 

2. [G™]± D ([0]</7= [0» 02 

3. -[Gj]± A [G,+i]± D i[0]ip EE [0» 1, 2, P, MP 

4. ^[Gj]± A [Gj+i]± D {[0']ip = [Gj]ip) ind. hyp. 

5. -[G,]± A [G,+i]± D ([O]^ = [G,]ip) 3,4, P, MP 

2. By induction on |(5(0)|: if \S{0)\ = 1, this is an instance of Gl. Assume this holds for modal operator [O], 
let us consider the proof for [O > «]. Let p and G denote respectively [S{0 > ?)]_L and S{0 > i) 

1. [0 > i]ip D D [G]ip) 01 

2. [0 > i](</7 D ^) D (^p D [G]((p D V)) 01 

3. [0 > i]ip D (p D [0]ip) 02 

4. [0 > i]{ip D ^p) D {p D [0]iip D ij)) 02 

5. [0 > i]ipA[0 > i]{ip D V) ^ hp 3 [G]tp) 1,2, G1,P, MP 

6. [0 > i]ipA [0 > i]{ip Di;)D {pD [0]^|J) 3,4, ind. hyp., P,MP 

7. [0 > i]ipA [0 > i]{ip D V) D l^p d[0> 5,01,P,MP 

8. [0 > i]ipA [0 > i]{ip Z) V) D (pD [O > i]^p) 6,02,P,MP 

9. [0 > i]ip A [0>i]{ipD V) D [O > # 7, 8, P, MP 

3. By induction on |(5(0)|: if |(5(0)| = 1, this is an instance of G2. Assume we have I — ^[0]±, then the proof of 
! — ^[O > i]± is as follows: 

1. -[(5(0 > i)]± D {[O > i]± D [5(0 > i)]±) 01 

2. [6{0 > i)]± D ([O > i]± D [0]±) 02 

3. [0 > i]± D [S{0 > i)]± 1,P,MP 

4. [0 > i]± D {[6(0 > t)]± D [0]±) 2, P, MP 

5. [0 > i]± D [0]± 3,4, P, MP 

6. -i[0]-L ind. hyp. 

7. ^[0>i]l. 5,6, P, MP 

4. By induction on |^(0)|: if 1^(0)1 = 1, this is an instance of Gen rule. Assume it is the case for modal operator 
[O] , let us consider the proof for [O > i] 

l.if Assumption 

2. [0]ip Ind. Hyp. 

3. [d{0 > i)](p Gen 

4. [0 > i]ip = ([(5(0 > i)]ip V [0]ip) 01, 02, P, MP 

5. [0>i]ip 2,3,4, P, MP 



□ 



A. 2 Proof of Theorem |T| 

The proof of the theorem is based on that for S5^ in As usual, the verification of the soundness part is a 

routine checking, so we focus on the completeness part. Let £ denote a logical system. A wff ip is £-inconsistent if 
its negation -lip can be proved in C. Otherwise, if is ^-consistent. A set E of wffs is said to be £-inconsistent if there 
is a finite subset {(pi, . . . , ipk} C T, such that the wff (pi A ■ ■ ■ A ipk is /^-inconsistent; otherwise, S is ^-consistent. 
A maximal /^-consistent set of wffs (£-MCS) is a consistent set x oi wffs such that whenever ip is a wff not in x, 
then X U {V'} is /^-inconsistent. 

On the other hand, (p is £-satisfiable iff there exists a C model M and a possible world w such that w 
if, otherwise ip is £-unsatisfiable. Sometimes the prefix C will be omitted without confusion. To prove the 
completeness, we will show that every DBF^-consistent wff is DBF^j-satisfiable. 



Let J = r On U 2^i'2...,n} _ {0} be the set of all modal operators for the language DBFf,. A pseudo DBFf, 
structure is a tuple {W, {TZ*j) i , V) where W and V are defined as in DBF^ models and each TZ*j is a binary 
relation on W. Furthermore, it is required that is a serial relation for each 1 < z < n. The satisfaction clauses 
for DBFJ^ wffs in pseudo structures arc defined as usual, so for example, we have w |= [0]ip iff for u E TZq{w), 
u \= if. What make difference is that in a pseudo structures, each TZj is considered as an independent relation 
instead of the intersection of other individual ones. A pseudo structure M* is called a pseudo model if all wffs 
provable in DBFJ^ are valid in M* . A DBF^^ wff (p is pseudo satisfiable if there exists a pseudo model M* and a 
possible world w such that w |=m* V- 

The following two results will be proved: 

Lemma A.l 1. If ip is DBF^^- consistent, then ip is pseudo DBF^-satisfiable. 
2. If ip is pseudo DBF^^-satisfiable, then it is DBFf^-satisfiable. 

The first result is proved by a standard canonical model construction procedure. A canonical pseudo structure 
M* = {W, (7^/)}gI, V) is defined as follows 

• = {w;^ I X is a DBF^j-MCS}, in other words, each possible world corresponds precisely to a DBFJ^^-MCS. 

• ^/(wxi'^X2) iff Xi/I C X2 for all I el, where xi/I = W I W'y' ^ xi}- 

• y : $0 -> 2^ is defined by V{p) = {w^ \ p e %}. 

The most important result for such construction is the truth lemma. 

Lemma A. 2 (Truth lemma) For any wff p and DBF^^-MCS x, we have \^m' P iff p E x- 

Proof: By induction on the structure of the wff, the only interesting case is the wff of the form [I]-!/) for some 
I GJ. By definition, \=m' [-f]^ iff for all w^i G TZ*j{w^), w^' \=m* ip iff for all x/I Q x\ ^ ^ x' (by induction 
hypothesis) iff x/I U {^^} is inconsistent iff [Ijip € x when [/] is a normal modal operator[^. However, by the 
axioms P and Gl, rules MP and Gen, and propositions |l|.2 and |l|.4, both kinds of modal operators [O] and [G] are 
normal ones. □ 

Since every DBFJ^-MCS contains all wffs provable in DBF^j, by the truth lemma, all provable wffs are valid in 
AI* . Furthermore, by axiom G2, each T^^y is serial for 1 < i < n. Thus M* is indeed a pseudo model. If p is 
DBF^-consistent, then there exists an MCS x contai ning p, so by the truth lemma, |=m* P, i-e., p is pseudo 



DBF^-satisfiable. This proves the first part of lemma A.l 



Note that if \X\ — m, then a pseudo model is in fact a model for the multi-agent epistemic logic Km|3l|]. The 
logic Km has m modal operators corresponding to the knowledge or belief of m independent agents. Admittedly, 
m may be a very large number, however, it does not matter for the current purpose. What is important is that it 
can be shown that without loss of generality, we can assume a pseudo model is tree-like. The detail definition of a 
tree-like model and the proof that each pseudo model can be "unwound" into a tree-like one verifying the same set 



of valid wffs are rather technical and can be found in ([^, pp. 354) and (|31 , Exercise 3.30). What is needed here 
is the property that in a tree-hke model, if / 7^ J, then TZ} fl Hj = 0. 

Thus, from now on, we can assume that if (p is DBF^-consistent, then p is pseudo DBF^-satisfiable in a tree-like 
model M* = (W, (7^})/gI,y). The next step is to construct a DBF^ model M = {W, (7^,)l<,<„, F) from M* by 
defining Hi = Uiec ^G- Note that TZi is serial since TZi 3 7?.| .| which is serial by the definition of pseudo models. 
From the definition, we can prove the following lemma. 

Lemma A. 3 For any w eW and wff p, w \=m* P iff w \=m P- 

Proof: By induction on the structure of p, the basis and classical cases are easy since both models have the same 
truth assignment function V. For the modal cases, it p — [G]ip, then w [G]fp iff for all u G f]-^QTZi{w), 
u \=M ip iff for all u G Ug'dg ^G' ''^ Hm* ip (by the definition of Hi, the tree-likeness of M* , and the induction 
hypothesis) iff w |=m» AgogI^']'/' (by definition of satisfaction in pseudo model M*) iff w \^m* [G]ip (since axiom 
G3 is vahd in M*). 

U p = [0]tp, then since proposition |l|.l is both valid in M* (by definition of pseudo models) and M (by 
soundness), and by the case for modal operators [G], we can find a j such that w satisfies the wff -i[Gj]_L A [Gj+i]_L 



(or just -i[Gj]_L in case of j = \S{0)\) in both M and M* , so it can be shown that w \=m [0]tp iS w [Gj]il' iff 
w ^M- [Gj]i; iff w hM* [O]^- □ 



This finishes the proof for the second part of lemma A.l and by combining the two parts, we have proved the 
completeness theorem for DBFJj. 

A.3 Proof of Theorem |2| 

The proof is very analogous to the previous one. What is different is that we do not have a counterpart 
for proposition |l|.l in the system DBF^. First, a pseudo DBFfj structure is analogously defined as a tuple 
{W, (7^si)0/ncTC>„ ; ^) Eind it is required that Tl^ij is serial for all 1 < i < rt. Then a pseudo DBFfj model is 
a pseudo DBF* structure in which all wffs provable in DBF^ are valid. 
We still have to prove the following lemma. 

Lemma A. 4 1. If ip is DBFf^- consistent, then ip is pseudo D B F!^- satis fiable. 

2. If ip is pseudo DBP^- satis fiahle, then it is DBF^-satisfiable. 

The first part of the lemma is proved exactly in the same way as in lemma [A.l| . It can also be obtained that if 
(fi is DBF^-consistent, then (p is pseudo DBFfj-satisfiable in a tree-like model AI* = {W, {TZ^)^^ficTO„iV). 

However, the proof of the second part is somewhat different. Let us define the level of a modal operator 
as = maxogn |<5(0)| and the length of H. as tt(ri) = the number of elements O in such that |(5(0)| = l{fl). 
Then we define a function Ag* : W x (2^'^" - {0}) ^ (2{i.2. -."} _ 0) from the model M* by 

r UoenAg*iwAO}) if\n\>l, 

An*hnO^-} A9*(^«,{0})U{z} ifn = {0>i}andw^M' ^[{0,i}]±, 

Ag[w,U)-< iin^{0>t}andw^M'[{0,i}]±, 

[ {*} ifQ = {i}, 

Note that since Ag*{w, fl) is a subset of agents, it can also be used as a modal operator of level 1. We can now 
construct a DBF^ model M = (W, (7^i)l<^<n, V) from M* such that 7^, U;(o)=i,»eo ^si- 
Lemma A. 5 1. For all w e W, modal operators Q, and wffs ip, we have w \^m* [f^]<y5 = [Ag*{w, ^)]'p. 

2. TZq{w) = y{^f2'(^) I ~ lAAg*(w,Cl) C fi'} for allw (liW and modal operators Q, where TZn is defined 
in section y. 

Proof: 

1. By induction on the level of Vl: 

The basis case l(yi) = 1: then by definition, Ag*{w, Q) — fi, so the result holds trivially. 
Assume the result holds for all SI such that 1{Q) < k, 
l{il) = fc + 1: by induction on the length of fi: 

jj(fi) = 1: let n== {O > i}U Qi, where < fc, then Ag*{w,n) = Ag*{w,{0 > i}) U Ag*{w,ni) = 

Ag*{w, {0})UAg*iw, ni)U{i} = Ag*{w, f^z) ff w ^m- -[{O, i}]± and = Ag*{w, {0})UAg*iw, fli) = 
Ag*lw,n3) ifw Hm- [{0,4]-L, where = {0,i}Ul7i and 17 3 = {OjUQi. Since ^(r^z) = ^(^^3) = k, 
then by induction hypothesis, we have w \=m* [f7i]<^ = [Ag*{w, Qi)]ip for i = 2,3, so by axioms 01' 
and 02' (recall that all axioms are valid in a pseudo model), w |=a/» [ri](/3 = [Ag*{w, ri)]</3 no matter 
whether w \=m* [{0,i}]l. or not. 

Assume the result holds for all fl such that jj(ri) < t: 

jJ(Sl) = i + 1: the induction step is completely the same as in the basis case except that l{^l2) = K^s) = 

fc + 1 but tJ(f72) = tt(f^3) = t. 

2. By induction on Z(S1): 



□ 



= 1: then Ag*{w, fi) = and by definition in section | 



iefi 



= \J{nh,{w)\i{n')^iAAg*{w,n)cn'} 

Assume the result holds for < k. 
= fc + 1: there are two cases 

= lei Q. = {O > i}, then by definition in section ^, we have 

nn{w) - no>M I ^^(^^ ^ otherwise, 
where by the induction hypothesis and the definitions of Ag* and TZi{w), 

T^o{w) ^[j{n*^.{w) I ^lhAg*{w,{0]) C n'} 

■Ro{w)rMl^{w) = |J{7^^y(^(7) | = I N Ag*{w,{0,i}) C n'}. 

On the other hand, by the result of first part, let fii — Ag*{w,{0,i\), then w \=m* [{0,?}]-L iff 
w \=M' iff w [f^']-L for aU W such that = 1 and C fi' (by axiom V3) iff 

7e^, [w] = for aU such Vl' iff 7eo(w) n 7^^(■^i;) = 0. Thus, by the definition of Ag* , 



Ag*{w,n) = 

and the result follows immediately, 
r^l > 1: by definition 



Ag*(w,{0}) \i'Ro{w)r\n^{w) =% 
Ag* {w , {O , {}) otherwise 



^n(w) = Pi Tlo{w) 

oen 

= n Ui^O'H I ^(^^0 ^lAAg*iw,{0}) C n'} 
oen 

= U{^0'(^«) I ^(f^') = 1 A U {O}) C f]'} 

= [J{n*^,{w)\i{n') = iAAg*{w,n)cn'} 



Finally, we can prove the counterpart of lemma A. 3 for DBF^ 
Lemma A. 6 For any w eW and wffip, w ip iff w ip. 
Proof: By induction on the structure of ip, the only interesting case is ip — ['^]ip-, 

w ^A/. [filip ^ w \^M* [Ag*{w,n)]ip (lemma ^.1) 

^ w \^M' [f^'l^A for aU fl' such that = 1 and Ag*{w, fl) C fl' (V3) 

^ u\^M- ip,yu e [J{n*^,{w) I = 1 A C 17'} 

^ u Ha^ '>P,yu G Tlfi{w) (induction hypothesis and lemma |A.5| .2) 

□ 

This completes the proof of the second part of lemma A. 4 and the completeness theorem for DBF^ . 



